Impact
Adobe Campaign Classic suffers from an OS command injection flaw that allows an attacker to run arbitrary code in the context of the current user. Because the vulnerability does not require user interaction, exploitation can occur automatically once the application processes malicious input. This weakness, identified as CWE‑78, directly compromises confidentiality, integrity, and availability of the system.
Affected Systems
Adobe Campaign Classic. Versions 7.4.4 build 9400 and 9401 are specifically affected per the CPE data; other deployments may also be at risk if they lack the patch.
Risk and Exploitability
The CVSS score of 10 signals a maximum severity vulnerability with the potential for complete system takeover. The EPSS score of 3% indicates a low but nonzero probability that this vulnerability is actively exploited. The fact that the flaw only needs the application to process data and that the scope is changed means that on exploitation the attacker could immediately alter or compromise the application’s entire environment. The issue is not listed in the CISA KEV catalog, but its high technical score and lack of user interaction barriers still make it a critical threat worthy of rapid remediation.
OpenCVE Enrichment